2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-24658 | MEDIUM | 5.9 | 0.3% | Jan 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joe Auction Nudge ... |
| CVE-2025-24657 | MEDIUM | 5.9 | 0.3% | Jan 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebToffee Wishlist... |
| CVE-2025-24652 | MEDIUM | 5.4 | 0.4% | Jan 24, 2025 | Missing Authorization vulnerability in revmakx WP Duplicate local-sync allows Exploiting Incorrectly Configured Access C... |
| CVE-2025-24649 | MEDIUM | 4.3 | 0.4% | Jan 24, 2025 | Missing Authorization vulnerability in Bowo Admin and Site Enhancements (ASE) admin-site-enhancements allows Exploiting ... |
| CVE-2025-24647 | MEDIUM | 5.4 | 0.2% | Jan 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in datafeedr WooCommerce Cloak Affiliate Links woocommerce-cloak-affilia... |
| CVE-2025-24644 | MEDIUM | 4.8 | 0.3% | Jan 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebToffee WooComme... |
| CVE-2025-24638 | MEDIUM | 6.5 | 0.3% | Jan 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pddring Create wit... |
| CVE-2025-24634 | MEDIUM | 5.9 | 0.3% | Jan 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Svetoslav Marinov ... |
| CVE-2025-24633 | MEDIUM | 5.3 | 0.4% | Jan 24, 2025 | Missing Authorization vulnerability in silverplugins217 Build Private Store For Woocommerce build-private-store-for-wooc... |
| CVE-2025-24627 | MEDIUM | 6.5 | 0.3% | Jan 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Linnea Huxford Blu... |
| CVE-2025-24625 | MEDIUM | 4.3 | 0.5% | Jan 24, 2025 | Missing Authorization vulnerability in Marco Almeida | Webdados Taxonomy/Term and Role based Discounts for WooCommerce t... |
| CVE-2025-24623 | MEDIUM | 4.3 | 0.2% | Jan 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Really Simple SSL really-simple-ssl allows Cros... |
| CVE-2025-24622 | MEDIUM | 5.4 | 0.2% | Jan 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in PickPlugins Job Board Manager job-board-manager allows Cross Site Req... |
| CVE-2025-24613 | MEDIUM | 4.3 | 0.4% | Jan 24, 2025 | Missing Authorization vulnerability in FolioVision FV Thoughtful Comments thoughtful-comments allows Exploiting Incorrec... |
| CVE-2025-24611 | MEDIUM | 4.9 | 0.7% | Jan 24, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Smackcoders Inc., WP Ult... |
| CVE-2025-24610 | MEDIUM | 6.5 | 0.4% | Jan 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Christian Leuenber... |
| CVE-2025-24604 | MEDIUM | 5.4 | 0.4% | Jan 24, 2025 | Missing Authorization vulnerability in Vikas Ratudi VPSUForm v-form allows Exploiting Incorrectly Configured Access Cont... |
| CVE-2025-24595 | MEDIUM | 6.5 | 0.4% | Jan 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins All Embed... |
| CVE-2025-24594 | MEDIUM | 6.5 | 0.5% | Jan 24, 2025 | Missing Authorization vulnerability in aribhour Linet ERP-Woocommerce Integration linet-erp-woocommerce-integration allo... |
| CVE-2025-24589 | MEDIUM | 4.3 | 0.4% | Jan 24, 2025 | Missing Authorization vulnerability in JS Morisset JSM Show Post Metadata jsm-show-post-meta allows Exploiting Incorrect... |
| CVE-2025-24588 | MEDIUM | 6.5 | 0.5% | Jan 24, 2025 | Missing Authorization vulnerability in patreon Patreon WordPress patreon-connect allows Exploiting Incorrectly Configure... |
| CVE-2025-24585 | MEDIUM | 6.5 | 0.4% | Jan 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bastien Ho Event p... |
| CVE-2025-24582 | MEDIUM | 5.3 | 0.9% | Jan 24, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in AA Web Servant 12 Step Meeting List 12-step-meeting-l... |
| CVE-2025-24580 | MEDIUM | 6.5 | 0.6% | Jan 24, 2025 | Missing Authorization vulnerability in AA Web Servant 12 Step Meeting List 12-step-meeting-list allows Exploiting Incorr... |
| CVE-2025-24579 | MEDIUM | 5.9 | 0.4% | Jan 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kyle Phillips Nest... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now